From 1cc7236ef67378387adad5fcb6d347ed6bdef775 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 5 Jun 2026 12:19:06 -0400 Subject: [PATCH] fix(ci): drop pull-requests write from callable-dependency-review (#40) Callers grant no explicit permissions, so they pass the org default read-only token. A reusable workflow cannot request more than its caller grants, causing startup_failure on every dependency-review run. dependency-review-action only needs contents: read when not posting PR comments. --- .github/workflows/callable-dependency-review.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/callable-dependency-review.yaml b/.github/workflows/callable-dependency-review.yaml index 646225b..a0a3f7a 100644 --- a/.github/workflows/callable-dependency-review.yaml +++ b/.github/workflows/callable-dependency-review.yaml @@ -3,7 +3,6 @@ on: workflow_call: permissions: contents: read - pull-requests: write jobs: dependency-review: runs-on: ubuntu-latest